Selesta Visual Access Manager
cpe:2.3:a:seling:visual_access_manager:*:*:*:*:*:*:*
- < 4.42.2
A vulnerability exists in Selesta Visual Access Manager (VAM) versions prior to 4.42.2, where an authenticated user can access the administrative page '/common/vam_Sql.php'. This page permits the execution of arbitrary SQL queries, potentially leading to unauthorized data manipulation or disclosure.
Exploitation of this vulnerability could allow an authenticated user to execute arbitrary SQL queries, which may be used to manipulate or extract sensitive data from the application's database.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.